Kernel Process Protect & Hide
ezpdb: https://github.com/i1tao/EzPDB
Compatible Win8 ~ Win11(24H2)
Protect:
-
PPL(PPL_AntiMalware)
-
APC(Anti ZwTerminateProcess, ZeroProcessMemory, TerminateThread, SuspendThread……) (PatchGuard WARNING!)
-
Set System Critical Process
-
Extract to SYSTEM
HideProcess:
- Set Pid 4
- Disconnection
- Destruction Process Features(BSOD WARNING!)